Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

516 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Qnap Helpdesk4/12/201917/6/2026
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
ModificadaMedia (6.5)1.3%—Otrs FAQOtrs Help DeskOtrs ItsmDebian Linux+127/11/201916/6/2026
An Access Bypass issue exists in OTRS Help Desk before 3.2.4, 3.1.14, and 3.0.19, OTRS ITSM before 3.2.3, 3.1.8, and 3.0.7, and FAQ before 2.2.3, 2.1.4, and 2.0.8. Access rights by the object linking mechanism is not verified
ModificadaCrítica (9.8)1.9%—Axohelp.c Project Axohelp.cAxodraw2 Project Axodraw229/10/201917/6/2026
In axohelp.c before 1.3 in axohelp in axodraw2 before 2.1.1b, as distributed in TeXLive and other collections, sprintf is mishandled.
ModificadaAlta (8.8)0.68%—Joomsky JS Help Desk27/8/201917/6/2026
The js-support-ticket plugin before 2.0.6 for WordPress has CSRF.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Zendesk Help Center16/8/201917/6/2026
The zendesk-help-center plugin before 1.0.5 for WordPress has multiple XSS issues.
ModificadaAlta (7.2)4.8%💥 PoCJitbit Helpdesk9/8/201917/6/2026
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The…
ModificadaMedia (5.5)0.41%—Docker Credential HelpersFedoraproject FedoraCanonical Ubuntu Linux29/7/201917/6/2026
docker-credential-helpers before 0.6.3 has a double free in the List functions.
ModificadaAlta (8.8)1.5%—Helpy.io Helpy10/7/201917/6/2026
Helpy before 2.2.0 allows agents to edit admins.
ModificadaCrítica (9.8)2.4%—Fehelper Project Fehelper26/6/201917/6/2026
FeHelper through 2019-06-19 allows arbitrary code execution during a JSON format operation, as demonstrated by the {"a":(function(){confirm(1)})()} input.
ModificadaMedia (6.1)0.88%—Helpy.io Helpy18/6/201917/6/2026
Helpy v2.1.0 has Stored XSS via the Ticket title.
ModificadaCrítica (9.8)1.2%—Helpsystems Boks8/2/201917/6/2026
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
ModificadaMedia (5.4)0.80%—Schiocco Support Board - Chat AND Help Desk17/10/201817/6/2026
In the Schiocco "Support Board - Chat And Help Desk" plugin 1.2.3 for WordPress, a Stored XSS vulnerability has been discovered in file upload areas in the Chat and Help Desk sections via the msg parameter in a /wp-admin/admin-ajax.php sb_ajax_add_message action.
ModificadaCrítica (9.8)2.3%—Qnap Helpdesk13/8/201817/6/2026
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
ModificadaAlta (7.5)1.1%—Lenovo Help13/7/201817/6/2026
The Lenovo Help Android app versions earlier than 6.1.2.0327 had insufficient access control for some functions which, if exploited, could have led to exposure of approximately 400 email addresses and 8,500 IMEI.
ModificadaAlta (7.5)1.0%—Helpproject Help9/7/201817/6/2026
The mintToken function of a smart contract implementation for HELP, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Lenovo Help19/4/201817/6/2026
Lenovo Help Android mobile app versions earlier than 6.1.2.0327 allowed information to be transmitted over an HTTP channel, permitting others observing the channel to potentially see this information.
ModificadaAlta (7.8)0.71%—Swisscom Tvmediahelper27/3/201817/6/2026
Swisscom TVMediaHelper 1.1.0.50 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary…
ModificadaAlta (8.8)0.58%—Userscape Helpspot19/2/201817/6/2026
An issue was discovered in Userscape HelpSpot before 4.7.2. A cross-site request forgery vulnerability exists on POST requests to the "index.php?pg=password.change" endpoint. This allows an attacker to change the password of another user's HelpSpot account.
ModificadaMedia (6.1)0.89%—Userscape Helpspot19/2/201817/6/2026
An issue was discovered in Userscape HelpSpot before 4.7.2. A reflected cross-site scripting vulnerability exists in the "return" parameter of the "index.php?pg=moderated" endpoint. It executes when the return link is clicked.
ModificadaMedia (6.1)2.9%—Adobe Robohelp1/12/201717/6/2026
Adobe RoboHelp has an Open Redirect vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
ModificadaMedia (6.1)2.8%—Adobe Robohelp1/12/201717/6/2026
Adobe RoboHelp has a cross-site scripting (XSS) vulnerability. This affects versions before RH12.0.4.460 and RH2017 before RH2017.0.2.
ModificadaAlta (7.5)2.6%💥 ExploitQnap QTS Helpdesk6/10/201717/6/2026
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
ModificadaMedia (5.4)0.60%—Mirasvit Helpdesk MX21/9/201717/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.
ModificadaAlta (8)1.4%—Mirasvit Helpdesk MX21/9/201717/6/2026
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.
ModificadaAlta (8.1)7.4%💥 ExploitHelpdeskpro Helpdesk PRO20/9/201717/6/2026
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
Orbitaley — Vulnerabilidades